Fraud Investigations & Financial Crime OSINT

Financial crime OSINT turns the traces fraudsters leave behind, such as domains, companies, phone numbers, payment details and social accounts, into names, networks and evidence. We investigate investment scams, impersonation, procurement and insider fraud for companies, insurers, banks and their lawyers.

  • Investment and impersonation fraud
  • BEC and payment diversion
  • Procurement and insider fraud
  • Evidence for police, regulators and courts
Short answer

Financial crime OSINT is the use of public and licensed sources to investigate fraud: who registered the domain, who directs the company that received the money, which other victims and fake brands share the same infrastructure, and where the proceeds went. OSINT-S identifies the people and networks behind a fraud and documents the evidence so your lawyers, the police or a regulator can act on it.

Fraud in Numbers: What 2025 Looked Like

Reported fraud losses reached new highs in 2025, led by investment scams and business email compromise, and most insider fraud ran for a year before discovery.

  • The FBI's Internet Crime Complaint Center received 1,008,597 complaints in 2025 with reported losses of $20.9 billion. Investment fraud accounted for $8.6 billion and business email compromise for $3.0 billion (FBI IC3 2025 report).
  • In the UK, criminals stole £1.28 billion through payment fraud in 2025, including £576.4 million through authorized push payment scams; investment scam losses of £221.5 million were the highest on record (UK Finance Fraud Report 2026).
  • The ACFE's 2026 study of 2,402 occupational fraud cases in 143 countries (ACFE) estimates organizations lose about 5% of revenue to fraud each year; the median case lost $104,000 and ran 12 months before detection (Accounting Today).

Behind most of these losses sit repeatable patterns: the same registration agents, hosting, phone ranges and recipient companies reused across many victims. That reuse is what an open-source investigation exploits.

Financial Fraud OSINT Investigations We Run

Six common case types. Each starts with what you already hold, such as emails, invoices, payment details or a website, and works outward.

Investment

Investment and trading scams

Fake platforms, clone firms and "advisers": who runs them, which entities received funds, and which other brands share the same operators.

Impersonation

BEC and payment diversion

Spoofed suppliers and executives, look-alike domains and changed bank details, traced to the infrastructure and the holders of recipient accounts.

Procurement

Procurement and vendor fraud

Shell suppliers, bid rigging and kickbacks: hidden links between vendors, employees and decision-makers.

Insider

Insider and occupational fraud

Undisclosed companies, conflicts of interest and lifestyle evidence, supported by employee screening where it applies.

Identity

Fake companies and identities

Counterparties that do not exist as claimed: borrowed registrations, stolen identities and fabricated track records.

Networks

Mule and recipient networks

The companies and people that receive and pass on fraud proceeds, mapped to support recovery and reporting.

How OSINT Identifies the People Behind a Fraud

Fraudsters reuse infrastructure. Each reused element, such as a domain registrant, phone number, photo or company officer, links one scheme to the next and eventually to a person.

A typical case begins with a handful of artifacts: a website, a few emails, an invoice with bank details, a phone number, perhaps a messaging handle. We expand each one. Domains lead to registration history, hosting, certificates and sibling sites. Recipient companies lead to directors, addresses and filing agents. Phone numbers and handles lead to accounts in other names. Photos of "advisers" lead to stock libraries or stolen profiles of real people.

The aim is a chart that connects the scheme to the people and companies who run or profit from it, with every link graded: confirmed by an independent record, likely, or only possible. Where the fraud ran through social platforms, we combine this with social media investigations; where funds left as cryptocurrency, with crypto investigations.

Evidence for Police, Regulators and Civil Recovery

Different audiences need different evidence. We agree the destination at the start so the report fits it.

AudienceWhat they needWhat we provide
Police and prosecutorsA clear account of the offense, identified suspects, and evidence they can verify and obtain formallyConcise referral pack: timeline, suspects, linked entities, preserved captures and the records officers can request
RegulatorsFirms or people acting without authorization, or failures in controlsEntity and individual profiles, links between clone firms, dated evidence of activity
Civil recovery lawyersDefendants to sue, assets to freeze, and grounds for disclosure orders against banks or platformsDefendant identification, asset tracing, and documented links that support applications
Insurers and boardsWhat happened, who is responsible, and whether controls failedFindings report with confidence grading and recommendations

Insurers handling fraud claims can see more on our page for insurance, and banks and payment firms on our page for financial services.

What to Do in the First 48 Hours

Report the fraud, call your bank, preserve everything, and do not confront the suspects. Speed matters most when money is still moving.

When fraud is reported quickly, money can sometimes be stopped. The FBI's Recovery Asset Team handled 3,900 incidents in 2025 through its Financial Fraud Kill Chain, with a 58% success rate and about $679 million frozen (FBI IC3 2025 report). That only works if the bank and the authorities hear about it in time.

So the first steps are yours: ask your bank to recall the payment, report to the police or IC3 in the US, keep the original emails with headers, invoices, chat logs and screenshots, and do not reply to the fraudster or warn suspected insiders. Brief us at the same time; we can start preserving the public side of the scheme, such as websites and accounts, before it disappears.

How a Fraud Investigation Runs

From your artifacts to identified people and a report shaped for its audience, with senior review before delivery.

  1. Brief and scopeYou share what you hold and the outcome you need: recovery, referral, dismissal or insurance. We confirm the lawful purpose, scope and a fixed quote in writing.
  2. PreserveWebsites, accounts, listings and registrations are captured with dates and technical details before they change.
  3. Expand and linkEach artifact is expanded into infrastructure, companies and accounts, and linked to other schemes and victims.
  4. Identify and verifyCandidate people and entities are confirmed against records created independently of the scheme, with confidence grades.
  5. Report and supportA senior analyst reviews the findings. You receive a report for its audience and a call with your lawyers or investigators.

Timelines, Legal Limits and When We Are the Wrong Call

Focused cases from 10 business days, lawful sources only, and a clear handover where police powers or court orders are needed.

A focused investigation into one scheme takes from 10 business days; complex, multi-country networks take up to about a month. Urgent work, for example before a freezing application, costs 50% more, and if we miss the agreed date, the fee goes down. Everything is confidential, under NDA where you need one.

We do not hack fraudsters back, pose as victims to extract information, or buy leaked data. Bank account holders and transaction records are obtained by police or by your lawyers through disclosure orders, not by us. Personal data is handled for a defined purpose and in proportion to it under the GDPR and UK GDPR (GDPR). If the main question is whether your onboarding controls work, KYC and AML support is the better fit. Fraud work is one of the OSINT services for fraud and compliance teams we run as one team.

OSINT Fraud Investigations: Specialized Services

Focused versions of fraud investigations for specific subjects, deals and situations.

Fraud investigations

Investment scam investigations

Fake trading platforms and clone firms traced to the companies, payment routes and people behind them, with evidence for lawyers and police.

Read more →
Fraud investigations

BEC investigations

Diverted payments traced: whose mailbox was used, the campaign behind it, the recipient account and companies, with evidence for banks and insurers.

Read more →
Fraud investigations

Procurement and vendor fraud

Fake vendors, kickbacks, hidden conflicts of interest and bid rigging: links between staff, suppliers and bidders found and documented.

Read more →

Find Out Who Is Behind the Fraud

Send what you have: emails, invoices, payment details, websites and the outcome you need. We reply with a scope, a timeline and a fixed quote.

Financial Crime OSINT FAQ

Our finance team paid a fake supplier invoice after a spoofed email — can financial crime OSINT identify who is behind the look-alike domain and the company that received our money?

Often, yes. We trace the look-alike domain's registration history, hosting and sibling domains, and investigate the company or person named on the receiving account: officers, addresses, filing agents and links to other schemes. The result is a set of identified people and entities graded by confidence, which your lawyers can use for disclosure orders and the police for a referral. Report the payment to your bank at once; speed matters for recall.

I invested with an online trading platform that stopped paying out — can you find out who really runs it and whether other people lost money to the same operators?

Usually. Platforms like this reuse templates, hosting, payment processors, support numbers and company agents across many brands. We map those links, identify the companies and people behind them, and look for regulator warnings, complaints and other victims. That helps a lawyer decide whether a claim or group action is realistic. If you were contacted by someone offering to recover your money for a fee, treat it as a likely second scam.

We suspect a procurement manager steered contracts to a supplier he secretly owns — how can a fraud investigation prove the link without tipping him off?

We look for connections between the manager and the supplier in public records: directorships and shareholdings, relatives as officers, shared addresses, phones, domains and accountants, and changes made around contract awards. We work only from outside sources, so nothing alerts him. Findings are graded so your HR and legal teams know what is confirmed before an interview or disciplinary step. Internal records such as emails remain for your own investigators.

Our insurer wants independent evidence before paying a crime claim under our policy — what will your report include and will it hold up if the claim ends in court?

The report sets out what happened, who was involved, how they are linked and how confident we are in each finding, with a source record for every fact: where it came from and when it was captured. Copies are kept. It is written so lawyers can adapt it into a witness statement, and the analyst can explain the method if needed. Agree the audience at the start so the format fits.

We're a bank compliance team looking for OSINT solutions for financial crime detection on suspicious customers — can you investigate the alerts our system can't resolve?

Yes. Automated screening clears most alerts; the rest need someone to look at who the customer really is, who controls the business and where the money comes from. We investigate escalated cases one by one with ownership, adverse media, sanctions links and network analysis, and return a written finding your team can file. For ongoing exposure, we can also monitor high-risk names on our analyst-reviewed platform, which updates hourly.

A former employee may have set up fake vendors before leaving last year — how long would an investigation take, and can you help us recover the money afterwards?

A focused investigation into a handful of vendors takes from 10 business days. We check whether each vendor exists as claimed, who owns and runs it, and how it links to the former employee. If the link is confirmed, we can move straight into asset tracing so your lawyers know what is recoverable and where. Recovery itself runs through civil claims or the police; we support both with evidence.